AdWare parasite

D

David

Hi all

I think my kids XP pc has been infested by the MyWebSearch toolbar - they
downloaded a "mesenger update" which resulted in IE being turned into an
add server for various adult sites- I have managed to get rid of the
constant
pop-ups and have restored the homepage but I can't get rid of the toolbar.
In the view toolbar menu "ytrtrdzstos" has appeared and I can't get rid of
it!! I unlock the toolbars, clear it, lock the toolbars again but next time
I start IE6 it's back!

I've tried SpyBot and NoAdd but with no success

Any advice?
 
M

mac

David said:
Hi all

I think my kids XP pc has been infested by the MyWebSearch toolbar - they
downloaded a "mesenger update" which resulted in IE being turned into an
add server for various adult sites- I have managed to get rid of the
constant
pop-ups and have restored the homepage but I can't get rid of the toolbar.
In the view toolbar menu "ytrtrdzstos" has appeared and I can't get rid of
it!! I unlock the toolbars, clear it, lock the toolbars again but next time
I start IE6 it's back!

I've tried SpyBot and NoAdd but with no success

Any advice?

Courtesy Jim Byrd, MS-MVP:

This is a CoolWebSearch variant. Do the following:

Download and run: http://www.merijn.org/files/cwshredder.zip to remove the
parasite. Be sure to close all instances of IE and OE. Always download a
fresh copy as this program is updated frequently.

Then download and run:
http://www.kellys-korner-xp.com/regs_edits/iegentabs.reg to restore your
tabs and remove any restrictions that the parasite has put in place.

However, this also indicates that you may have acquired some other malware
along the way. If you go to this page at Jim Eshelman's site, here:
http://aumha.org/a/noads.htm and wait a little bit (be patient), an analysis
of a number of possible parasites on your machine will be made to help you
identify and remove them. NOTE: You will need to disable Ad Blocking in Zone
Alarm 3.x, if present or any other Ad Blocking software which interferes
with Java Scripting for this scan to work. You should get a message between
the two lines of **** giving the results of the scan.

Get Ad-Aware 6.0, Build 181 or later, here:
http://www.lavasoftusa.com/support/download/. Update and run this regularly
to get rid of most "spyware/hijackware" on your machine. If it has to fix
things, be sure to re-boot and rerun AdAware again and repeat this cycle
until you get a clean scan. The reason is that it may have to remove
things which are currently "in use" before it can then clean up others.

Another excellent program for this purpose is SpyBot Search and Destroy
available here: http://security.kolla.de/ SpyBot Support Forum here:
http://www.net-integration.net/cgi-bin/forums/ikonboard.cgi. I recommend
using both normally. After fixing things with SpyBot S&D, be sure to
re-boot and rerun SpyBot again and repeat this cycle until you get a clean
"no red" scan. The reason is that SpyBot sometimes has to remove things
which are currently "in use" before it can then clean up others.



Note that sometimes you need to make a judgement call about what these
programs report as spyware. See here, for example:
http://www.imilly.com/alexa.htm

Once you get this cleaned up, you might want to consider installing the
SpywareBlaster and SpywareGuard here to help prevent this kind of thing from
happening in the future:

http://www.wilderssecurity.com/spywareblaster.html (Prevents malware Active
X installs) (BTW, SpyWare Blaster is not memory resident ... no CPU or
memory load - but keep it updated) The latest version as of this writing
will prevent installation or prevent the malware from running if it is
already installed, and it provides information and fixit-links for a variety
of parasites.

http://www.wilderssecurity.net/spywareguard.html (Monitors for attempts to
install malware) Both Very Highly Recommended
 
S

siljaline

David said:
Hi all

I think my kids XP pc has been infested by the MyWebSearch toolbar - they
downloaded a "mesenger update" which resulted in IE being turned into an
add server for various adult sites- I have managed to get rid of the
constant
pop-ups and have restored the homepage but I can't get rid of the toolbar.
In the view toolbar menu "ytrtrdzstos" has appeared and I can't get rid of
it!! I unlock the toolbars, clear it, lock the toolbars again but next time
I start IE6 it's back!

I've tried SpyBot and NoAdd but with no success

Any advice?

Lavasoft's Ad-aware rids of this pest.
http://www.lavasoft.de/news/product/october.shtml
Ad-aware download, http://www.lavasoftusa.com

Please post back if should require further assistance.

HTH

--
siljaline

MS - MVP Windows IE/OE
______________________

(Reply to group, as return address
is invalid - that we may all benefit)
 
G

Gerry O

Hello David,

Becareful, I read today that ad-aware from lavasoft can cause pop-ups
to appear and they apparently lay the blame on some spyware program,
sounds fishy to me. I would un-install ad-aware if I were you, until
they resolve their issues.

Gerry
IBM PC Specialist
 
D

David

Agree about ad-aware - I removed it from my own pc a couple of month ago
after a few oddities appeared - all has been well since.
On the kids PC I cannot get rid of the extra toolbar. SpyBot removed a few
references to other programs and now scans clean but the toolbar keeps
re-apearing.
I have removed IE and downloaded a fresh copy from Microsoft but same
problem with the "new" IE. Where in the registry does it keep its settings?
 
D

David

MAny thanks Mac

Both Xp pc's are now back to normal. the shredder didn't find anything (I
think I had removed all traces of the infecting files and their reg
settings) but the registry patch has done the trick.

I think I'll have to review the family security policy!!!!

Thanks again

David
 
D

David

Just tested the "fix" (You can take liberties with other peoples pc's
<eg> )

To completely remove the toolbar from an infected PC I had to do a reg
search using the filename of the toolbar in IE6 - a random string of letters
which changes each time it re-infects the PC - and delete every entry
containing the string - I think there were about 6 separate entries.

In combination with the reg patch and AddWare removal tools that seems to do
the trick

Good luck to anyone else infested with this!

David
 
S

siljaline

Gerry O said:
Hello David,

Becareful, I read today that ad-aware from lavasoft can cause pop-ups
to appear and they apparently lay the blame on some spyware program,
sounds fishy to me. I would un-install ad-aware if I were you, until
they resolve their issues.

Lavasoft's Ad-aware is a stable an application you can get.
What you claim to have read, is _total rubbish.

Post the URL that you *fail* to mention for us to review.
--
siljaline

MS - MVP Windows IE/OE
______________________

(Reply to group, as return address
is invalid - that we may all benefit)
 
F

Frank Saunders, MS-MVP IE/OE

Gerry O said:
Hello David,

Becareful, I read today that ad-aware from lavasoft can cause pop-ups
to appear and they apparently lay the blame on some spyware program,
sounds fishy to me. I would un-install ad-aware if I were you, until
they resolve their issues.

Gerry
IBM PC Specialist

Where do people get this nonsnse?
 
G

Guest

The same place they get chain letters claiming to know when you have sent it to 15 people - AOL

You would think people would do a little more research before believing that Bill Gates sent them a personal letter stating he would pay them if they forwarded "this" message to all their friends... The truth is out there... you just have to Google for it!


Warm Regards,

Raven Cecil, MCSP, MVP
Senior Network Engineer
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top